Critical Unauthenticated Access Flaw Found in Grafana OnCall
A critical vulnerability in Grafana OnCall allows unauthenticated remote attackers to gain full administrative access via hardcoded default identifiers.
Grafana OnCall versions up to 1.16.11 are affected by a critical vulnerability, tracked as CVE-2026-63087, which permits unauthenticated remote attackers to obtain a valid PluginAuthToken. By sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id values found in the public source tree, an attacker can bypass authentication mechanisms.
Once a token is acquired, attackers can authenticate against all internal API endpoints. This access allows for the creation of arbitrary Admin users, the revocation of legitimate tokens, and the redirection of API traffic to attacker-controlled hosts by overwriting organization configurations. With a CVSS score of 9.8, this vulnerability poses a significant security risk to affected systems.
Sources
- GitHub Security Advisories Original source
Continue Reading
FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen
Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.
Anthropic tackles Claude session hijacking via infostealers
Anthropic warns that infostealer malware is stealing Claude login sessions to drain accounts.
AI agents can be tricked into installing malware via unclaimed code packages
Researchers found 120 unregistered domains in AI documentation that could be hijacked to infect corporate networks.